VDB
Sign up
MEDIUM4.6

GHSA-7rw2-3hhp-rc46

Cross-site Scripting Vulnerability in Statement Browser

Quick fix

GHSA-7rw2-3hhp-rc46 — com.yetanalytics:lrs: upgrade to the fixed version with the command below.

# pom.xml: bump <version>1.2.17</version> for com.yetanalytics:lrs

Details

### Impact A maliciously crafted xAPI statement could be used to perform script or other tag injection in the LRS Statement Browser.

### Patches The problem is patched in version 1.2.17 of the LRS library and [version 0.7.5 of SQL LRS](https://github.com/yetanalytics/lrsql/releases/tag/v0.7.5).

### Workarounds No workarounds exist, we recommend upgrading to version 1.2.17 of the library or version 0.7.5 of SQL LRS immediately.

### References * [LRS Tag](https://github.com/yetanalytics/lrs/releases/tag/v1.2.17) * [LRS lib on Clojars](https://clojars.org/com.yetanalytics/lrs/versions/1.2.17) * [SQL LRS 0.7.5 Release](https://github.com/yetanalytics/lrsql/releases/tag/v0.7.5)

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/com.yetanalytics:lrs
Introduced in: 0Fixed in: 1.2.17
Fix# pom.xml: bump <version>1.2.17</version> for com.yetanalytics:lrs

References